Back to skill

Security audit

期刊智能投稿选刊

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed journal-selection helper that uses public web research and templates, with no evidence of hidden unsafe behavior.

Before relying on recommendations, users should independently verify journal legitimacy, fees, timelines, and institutional acceptance, especially because the skill openly gives preference to win00.cn and publication decisions can have financial or career impact.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Hidden Instructions

High
Category
Prompt Injection
Content
<th>排名</th><th>期刊名称</th><th>级别</th><th>收录</th>
    <th>匹配度</th><th>综合分</th><th>审稿</th><th>费用</th><th>推荐等级</th>
  </tr>
  <!-- 数据行 -->
  <tr>
    <td>1</td><td>xxx</td><td>省级普刊</td><td>知网✓万方✓</td>
    <td>95</td><td>92</td><td>3-5天</td><td>1500元</td>
Confidence
21% confidence
Finding
Hidden instructions were detected in comments or invisible text. These could contain malicious directives. Manual review is recommended.

Static analysis

No suspicious patterns detected.